CVE-2018-9173

MEDIUM

GetSimple CMS 3.3.13 - Cross-Site Scripting via uploadify.swf movieName Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2018-9173. PoCs published by Sureshbabu Narvaneni.

AI-analyzed exploit summary This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.13 via the 'movieName' parameter in the SWF file. The PoC includes URLs that trigger JavaScript alerts and cookie theft.

Description

Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.

Exploits (1)

exploitdb WORKING POC
by Sureshbabu Narvaneni · textwebappsphp
https://www.exploit-db.com/exploits/44408

This exploit demonstrates a Cross-Site Scripting (XSS) vulnerability in GetSimple CMS 3.3.13 via the 'movieName' parameter in the SWF file. The PoC includes URLs that trigger JavaScript alerts and cookie theft.

Classification
Working Poc 100%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: GetSimple CMS 3.3.13
No auth needed
Prerequisites: Access to the vulnerable SWF file URL
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://github.com/GetSimpleCMS/GetSimpleCMS/issues/1266
Exploit, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44408/

Scores

CVSS v3 6.1
EPSS 0.0250
EPSS Percentile 82.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (1)
get-simple/getsimple_cms 3.3.13
Published Apr 02, 2018
Tracked Since Feb 18, 2026